[Full-disclosure] TheGreenBow VPN Client tgbvpn.sys DoS and Potential Local

2009-08-18 Thread evil fingers
Original Advisory Link: https://www.evilfingers.com/advisory/Advisory/TheGreenBow_VPN_Client_tgbvpn.sys_DoS.php ---[TheGreenBow VPN Client tgbvpn.sys DoS and Potential Local Privilege Escalation]- Author: Giuseppe 'Evilcry'

[Full-disclosure] Vtiger CRM 5.0.4 Multiple Vulnerabilities

2009-08-18 Thread ascii
20090818 I. BACKGROUND Vtiger CRM is a free, full-featured, 100% Open Source CRM software ideal for small and medium businesses, with low-cost product support available to production users that need reliable support. II. DESCRIPTION Multiple Vulnerabilities exist in Vtiger CRM software. Some

Re: [Full-disclosure] (USA) Fighting the tyranny of fusion centers / JTTF harassment and profiling

2009-08-18 Thread someone lawyer
List, I ask you not make false statements involving my client. some...@lawyer.com - Original Message - From: ask...@hushmail.com To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] (USA) Fighting the tyranny of fusion centers / JTTF harassment and profiling Date:

[Full-disclosure] Safari buffer overflow

2009-08-18 Thread Leon Juranic
Three weeks ago, I coded a nice little browser fuzzer, and started playing with various browsers: IE, Firefox, Safari, Chrome, Opera... I found an interesting Safari crash after couple of hours of fuzzing. It was a stack overflow (and a smile on my face). Since then, every now and then I took

[Full-disclosure] Drupal flag module xss vulnerability

2009-08-18 Thread Justin Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Vulnerability Summary Report Author: Justin C. Klein Keane jus...@madirish.net Disclosure URL: http://lampsecurity.org/drupal-flag-module-vulnerability Description of Vulnerability: - - - Drupal (http://drupal.org) is a

[Full-disclosure] Cisco Security Advisory: Cisco Security Advisory: Cisco IOS XR Software Border Gateway Protocol Vulnerability

2009-08-18 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Security Advisory: Cisco IOS XR Software Border Gateway Protocol Vulnerability Advisory ID: cisco-sa-20090818-bgp http://www.cisco.com/warp/public/707/cisco-sa-20090818-bgp.shtml Revision 1.0 For Public Release 2009

[Full-disclosure] Information disclosure on Netgear WNR2000

2009-08-18 Thread Jean Trolleur
Dere is several mino' vulnerabilities on de Netgear WNR2000 wireless routa' runnin' firmware 1.2.0.8. 1. Unaudenticated disclosho' man uh WPA/WPA2 passwo'd, dig dis: Simply request widout audenticashun: http://netgear/router-info.htm http://netgear/cgi-bin/router-info.htm De routa' gots'ta

[Full-disclosure] False statements made about security researcher n3td3v

2009-08-18 Thread someone lawyer
List, Below are (malice) false statements about my client. Thu Jul 16 13:54:34 BST 2009 ureleet at gmail.com n3td3v is posting as ant-sec he is hacking and spreading disinformation on full-d. http://lists.grok.org.uk/pipermail/full-disclosure/2009-July/069692.html Sun Jul 26 02:40:47 BST

Re: [Full-disclosure] False statements made about security researcher n3td3v

2009-08-18 Thread Andrew Kuriger
Dude really? Nice signature: Be Yourself @ mail.com! Choose From 200+ Email Addresses Get a Free Account at www.mail.com! Nobody cares. I just find it funny. On Tue, 18 Aug 2009 14:43:15 -0500, someone lawyer some...@lawyer.com wrote: List, Below are (malice) false statements about my

Re: [Full-disclosure] False statements made about security researcher n3td3v

2009-08-18 Thread Sub
dont feed the troll ;) Andrew Kuriger schrieb: Dude really? Nice signature: Be Yourself @ mail.com! Choose From 200+ Email Addresses Get a Free Account at www.mail.com! Nobody cares. I just find it funny. On Tue, 18 Aug 2009 14:43:15 -0500, someone lawyer some...@lawyer.com wrote:

[Full-disclosure] CA20090818-02: Security Notice for CA Internet Security Suite

2009-08-18 Thread Kotas, Kevin J
-BEGIN PGP SIGNED MESSAGE- CA20090818-02: Security Notice for CA Internet Security Suite Issued: August 18, 2009 CA's technical support is alerting customers to a security risk with CA Internet Security Suite. A vulnerability exists that can allow a local attacker to cause a denial of

[Full-disclosure] CA20090818-01: Security Notice for CA Host-Based Intrusion Prevention System

2009-08-18 Thread Kotas, Kevin J
-BEGIN PGP SIGNED MESSAGE- CA20090818-01: Security Notice for CA Host-Based Intrusion Prevention System Issued: August 18, 2009 CA's technical support is alerting customers to a security risk with CA Host-Based Intrusion Prevention System. A vulnerability exists that can allow a remote

Re: [Full-disclosure] False statements made about security researcher n3td3v

2009-08-18 Thread someone lawyer
List, What funny about my client be targeted by internet trolls? some...@lawyer.com - Original Message - From: Andrew Kuriger To: Full-disclosure@lists.grok.org.uk Cc: Full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] False statements made about security researcher

[Full-disclosure] [ GLSA 200908-05 ] Subversion: Remote execution of arbitrary code

2009-08-18 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200908-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200908-06 ] CDF: User-assisted execution of arbitrary code

2009-08-18 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200908-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200908-07 ] Perl Compress::Raw modules: Denial of Service

2009-08-18 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200908-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200908-08 ] ISC DHCP: dhcpd Denial of Service

2009-08-18 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200908-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200908-09 ] DokuWiki: Local file inclusion

2009-08-18 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200908-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200908-10 ] Dillo: User-assisted execution of arbitrary code

2009-08-18 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200908-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] CORE-2009-0727: Libpurple msn_slplink_process_msg() Arbitrary Write Vulnerability

2009-08-18 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Libpurple msn_slplink_process_msg() Arbitrary Write Vulnerability 1. *Advisory Information* Title: Libpurple msn_slplink_process_msg() Arbitrary

Re: [Full-disclosure] False statements made about security researcher n3td3v

2009-08-18 Thread Valdis . Kletnieks
On Tue, 18 Aug 2009 15:52:36 CDT, someone lawyer said: What funny about my client be targeted by internet trolls? The self-referential aspects of the situation. pgpivnybqtd3v.pgp Description: PGP signature ___ Full-Disclosure - We believe in it.

[Full-disclosure] [ MDVSA-2009:206 ] wget

2009-08-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:206 http://www.mandriva.com/security/

Re: [Full-disclosure] False statements made about security researcher n3td3v

2009-08-18 Thread someone lawyer
List, My client setup a mailing list called n3td3v, he used the user n3td3v to spread the name of the user group so people would know it, since then you have ridiculed and tormented him, to the degree that he was so upset he had to be removed from your list. There was no need for you to do